Ship fast, stay secure: from code to runtime | OD841

James Brotsos presents an end-to-end view of how security can be embedded into developer workflows without forcing major process changes, using GitHub Advanced Security and Microsoft Defender for Cloud.

Overview

The session focuses on shifting security left (into code and pull requests) while also connecting findings to runtime and cloud risk.

What problem the session addresses

Security embedded into developer workflows

Defender for Cloud + GitHub Advanced Security integration

Demo: MDASH scanning pipeline

AI-assisted remediation with Copilot

Security manager view and dashboards

Connecting code vulnerabilities to cloud risk

GitHub workflow integration

AI model security

End-to-end security lifecycle

Resources